Live data from Hacker News

Sony: All personal data stolen from PSN

blog.us.playstation.com

41–50 of 292 posts

Re: Sony: All personal data stolen from PSN

#41

Earlier quoted context omitted.

Time to get a new identity! =) That's what I was thinking: in most cases of user accounts being compromised, the solution is "change your passwords on this and other sites". Here you need to change your birthday, cancel your credit card, move out, change your name… kind of a hassle.

> Here you need to change your birthday And, you know, your mom probably won't be too happy when you pop out of your time machine, a week before your birth, and tell her she needs to induce labor.

I think you just solved the problem. The shock would probably do it for you.

Re: Sony: All personal data stolen from PSN

#42
post #5

Earlier quoted context omitted.

You can diss your competitor for poor security practices only if you have some confidence in your own.

>You can diss your competitor for poor security practices only if you have some confidence in your own. Nope, companies usually don't leave any chance to point to the competition's faults and laugh, even if they themselves are worse in that regard.

It does carry a risk though - if you make securing a major online service sound too easy by ridiculing your competitor then down the line when you get breached its more damaging imo. eg I dont remember any Car companies in recent history pointing to Service recalls of their competitors in their advertisements, ditto for Airlines and crashes.

Re: Sony: All personal data stolen from PSN

#43
post #36
post #11

I wonder how many times a company can install trojans on your computer, destroy your OS's security, secretly watch all your actions, then proceed to not properly protect your data when you voluntarily give it to them...before going out of business. Sony's size and momentum must be pretty crazy. Or maybe it's our society. I just can't imagine a small record store in the 1960s, after being caught spying through the bed…

People want to play God of War, Little Big Planet and Gran Turismo. I think Sony could do just about anything and stay in business. As sad as that is, it's probably true.

I know, right? Reading through the comments on that post, the "you should have told us this last week" comments are just about balanced out by the "why are you wasting time with this instead of getting the PSN back online" comments.

Re: Sony: All personal data stolen from PSN

#44
They say passwords were stolen. This must mean they are not properly hashing passwords with salts stored outside of the database.

How many times does this have to happen before people realize that passwords are never to be stored in plaintext? The only exception is a client-side program that needs to log you in and in an ideal world that would be handled by a Kerberos-like ticket system.

Re: Sony: All personal data stolen from PSN

#45
post #32

Earlier quoted context omitted.

Time to get a new identity! =) That's what I was thinking: in most cases of user accounts being compromised, the solution is "change your passwords on this and other sites". Here you need to change your birthday, cancel your credit card, move out, change your name… kind of a hassle.

no problem! http://www.fakenamegenerator.com/

How do they claim to own the MX for example.com? Aren't the example.* domains supposed to be reserved?

Re: Sony: All personal data stolen from PSN

#47
Wow this sounds really really bad. As much as I dislike sony's actions in the Geohot case, and as much as "this is what you get for failing at security", I feel pretty bad for them right now (and even worse for all of their customers)

>To protect against possible identity theft or other financial loss, we encourage you to remain vigilant, to review your account statements and to monitor your credit reports.

>We have also provided names and contact information for the three major U.S. credit bureaus below. At no charge, U.S. residents can have these credit bureaus place a “fraud alert” on your file that alerts creditors to take additional steps to verify your identity prior to granting credit in your name.

Re: Sony: All personal data stolen from PSN

#48
post #14
post #8

FTA: we believe that an unauthorized person has obtained the following information that you provided: ...PlayStation Network/Qriocity password and login... I'm curious if this means they store everyone's password in plain-text, or if by "password" they really mean a hash of some sort.

Frankly I'm more concerned with their words about changing credit cards if you've made a purchase through PSN. This seems to be an admission that they were storing CC#'s in plain text.

How do you use stored credit card info if the cc# is not stored?

Unlike passwords, the encryption for the cc#s has to be reversible. That's part of the reason why they introduced CVCs, right?

Re: Sony: All personal data stolen from PSN

#49

I'm disappointed but not surprised. When I had to change my password a few months ago on the Sony developer's network site I was told that my new password was too similar to the last ones. I was wondering how they knew that, aside from storing the passwords in plain-text, something I'd assume they'd be too smart to do. I guess I gave them too much credit.

Genuine Question: They let you change your password without having you supply the old one?

Re: Sony: All personal data stolen from PSN

#50
post #3

Holy Cow! This has to be one of the most serious breaches I remember in recent times. While I dont work in security and my security foo is weak it appears that they did not have a strong layered security apparatus in place? Is it just a coincidence that this breach and geohotz exploit happened around the same time?

It really looks like the PSN architecture assumed that the clients were trustworthy. If so, that's an epic Security 101 fail.

And they used the same servers for development as for production. Isn't that non-PCI-compliant?
Post reply on HN